live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
releaseSECURITY

OpenShift 4.19.45 security fixes require the full release payload

The update spans RPM packages and container images; Red Hat advises all 4.19 clusters to move to 4.19.45 and provides no general workaround for most flaws.

OpenShift update split into packages and images.
AI-generated illustration
By The News Desk· Sep 3, 2026

OpenShift Container Platform 4.19.45 is a split security update: one Red Hat advisory carries RPM packages and another carries the release’s container images. Operators need the complete 4.19.45 payload rather than a hand-picked package update.

RHSA-2026:60452 is rated Important and fixes two package-level issues. The CRI-O fix prevents an /etc/passwd injection path using the HOME environment variable. The Go JOSE libraries fix a denial of service triggered by a crafted JSON Web Encryption object.

RHSA-2026:60454 supplies the container images and identifies four additional CVEs. Red Hat’s image advisory lists the full set of refreshed platform images, including control-plane operators, networking, monitoring, console, OAuth and bare-metal components, but it does not map each CVE to one image in the overview.

What the image CVEs affect

Two flaws are unauthenticated resource-exhaustion paths in Go libraries. CVE-2026-33814 lets a remote peer send an HTTP/2 settings frame that drives the Go transport into an infinite continuation-frame loop. CVE-2026-39829 lets an unauthenticated SSH client submit an oversized RSA or DSA public key and consume CPU during verification.

The higher-impact conditional exposure is CVE-2026-43003 in ironic-python-agent: a malicious partition image can cause code execution when the agent runs grub-install inside that image’s chroot. That matters specifically to bare-metal provisioning workflows that accept or process an attacker-controlled image.

CVE-2026-59869 is a denial of service in js-yaml when an application parses a crafted chain of YAML mappings with merge keys. Red Hat’s CVE page suggests restricting untrusted YAML processing as a way to reduce exposure.

Is there a mitigation short of upgrading?

For the Go HTTP/2, Go SSH and ironic-python-agent flaws, Red Hat says no mitigation is available that meets its criteria for broad, stable deployment. The js-yaml page offers exposure reduction—restrict and validate untrusted YAML—but that is not a replacement for the fixed image. The release advisories therefore tell all OpenShift 4.19 users to upgrade when 4.19.45 is available in their release channel.

What operators should verify

Before starting, confirm the cluster is on the 4.19 minor and that 4.19.45 is offered in the configured channel. Review cluster health and degraded operators, then start the normal OpenShift update rather than updating host RPMs or platform images independently.

After completion, verify that ClusterVersion reports 4.19.45 and that all ClusterOperator resources are Available without Progressing or Degraded conditions. Check MachineConfigPool completion where applicable, and verify bare-metal provisioning and ingress/API availability. Clusters that process untrusted bare-metal images or YAML should treat those workflows as the priority validation paths.

The operational answer is straightforward: there is no extra universal mitigation package for 4.19 operators. Move the cluster to the full 4.19.45 release payload and verify that both node/package changes and refreshed platform images converged.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.